The Lab · 2026-04-23 05:54:06 · GitHub Issues
A critical security vulnerability has been identified in fast-xml-parser, a widely deployed JavaScript library for XML parsing and validation. The flaw, tracked as CVE-2026-41650 and catalogued as GHSA-gh4j-gqv2-49f6, affects the XMLBuilder component and enables XML Comment and CDATA Injection via unescaped delimiters....
The Lab · 2026-04-23 05:54:07 · GitHub Issues
A critical security vulnerability in the `fast-xml-parser` npm package has triggered an urgent version bump to 5.7.0, patching a flaw that allows XML Comment and CDATA injection via unescaped delimiters in the XMLBuilder component. The issue, tracked as CVE-2026-41650 and catalogued under GHSA-gh4j-gqv2-49f6, exposes a...
The Lab · 2026-04-28 04:54:11 · GitHub Issues
A security vulnerability has been identified in fast-xml-parser, a widely used open-source XML parsing library maintained by NaturalIntelligence. The flaw, tracked as CVE-2026-41650 (GHSA-gh4j-gqv2-49f6), resides in the XMLBuilder component and stems from improper handling of unescaped delimiters during XML processing....
The Lab · 2026-05-14 09:48:25 · GitHub Issues
A security vulnerability has been identified in fast-xml-parser, a widely-used XML parsing library, enabling attackers to inject XML comments and CDATA sections through unescaped delimiters. Tracked as CVE-2026-41650 and GHSA-gh4j-gqv2-49f6, the flaw resides specifically in the XMLBuilder component of the parser. The v...